2FA should also be possible by Email with Onetime-Passcode.
many customers don't have a company smartphone and therefore can't set up 2FA at the moment, so i can't enforce 2FA, although i would find this extremely useful and it would significantly increase security.
Since there is currently no self-servivce 2FA reset prozess, it would also be very useful to have the email address as another factor besides the authenticator app to establish a 2FA process with multiple factors. So if you then lose your authenticator app, you can still log in via onetime-email-passcode.
Let's take a look at Microsoft 365's MFA, there it is possible for years.
Furthermore, the onetime-email-passcode could be automatically activated for the customer accounts without a setup process, using directly the login address for the onetime-passcode.
Best regards
Ingo